Hierarchical Network Control System for Public Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public datacenters often lack robust and transparent security capabilities, making companies hesitant to move their networks into these environments due to the inability to exercise direct security control over virtualization software and forwarding elements.

Innovation Solution

A hierarchical network control system that manages logical networks across private and public datacenters by operating network controllers and managed forwarding elements within virtual machines in public datacenters, enabling the enforcement of network security and forwarding rules through a gateway controller and local control agents, and utilizing distributed network encryption for secure traffic management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If companies move their networks to public datacenters to reduce costs and physical server burdens, then cost and maintenance burden are reduced, but security control capability deteriorates because the public datacenter owner controls the virtualization software and forwarding elements

Engineering Contradiction:
Improvecost and maintenance burdenVSAvoidsecurity control capability
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent introduces a network control system as an intermediary layer between the public datacenter infrastructure and the customer's network workloads. This control system includes controllers that manage forwarding elements and security policies, acting as a mediator that enables customers to exercise security control without directly managing the underlying virtualization software controlled by the public datacenter owner.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the network control system operates without access to virtualization software in public datacenters, then deployment flexibility is improved, but security policy enforcement capability deteriorates

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidsecurity policy enforcement capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The control system uses intermediary components including controllers that communicate with forwarding elements through standardized interfaces, and security policies that are enforced at the forwarding element level without requiring direct access to virtualization software. This intermediary architecture enables deployment flexibility while maintaining security policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network control functionality into separate components: controllers that manage policy and configuration, forwarding elements that handle packet processing, and security modules that enforce policies. This segmentation allows the control system to operate independently of the virtualization software while maintaining comprehensive security control.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3731463B1Extension of network control system into public cloud
Publication Date: 2022.03.30 NICIRA INC
  • EP3731463B1 patent drawingFigure 1
  • EP3731463B1 patent drawingFigure 2
  • EP3731463B1 patent drawingFigure 3~4

AI summary

Some embodiments provide a method for a first network controller that manages a logical network implemented in a datacenter including forwarding elements to which the first network controller does not have access. The method identifies a first data compute node (DCN) in the datacenter configured to execute a second network controller. The method distributes configuration data defining the logical network to the first DCN. The second network controller distributes sets of the configuration data to local agents executing on additional DCNs in the datacenter that send and receive messages through the logical network. Both managed forwarding elements and the local agents execute on each of the additional DCNs. Each local agent on a particular DCN is for receiving a set of configuration data from the second network controller and configuring the managed forwarding element on the particular DCN to implement the logical network according to the set of configuration data.